Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-5263

Опубликовано: 09 апр. 2026
Источник: debian

Описание

URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c. A compromised or malicious sub-CA could issue leaf certificates with URI SAN entries that violate the nameConstraints of the issuing CA, and wolfSSL would accept them as valid.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wolfsslfixed5.9.1-0.1package
wolfsslno-dsatrixiepackage
wolfsslno-dsabookwormpackage
wolfsslpostponedbullseyepackage

Примечания

  • https://github.com/wolfSSL/wolfssl/pull/10048

  • Fixed by: https://github.com/wolfSSL/wolfssl/commit/ce74def87775dbcf5e221f0361b43d0746ea5710 (v5.9.1-stable)

Связанные уязвимости

CVSS3: 6.5
ubuntu
4 месяца назад

URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c. A compromised or malicious sub-CA could issue leaf certificates with URI SAN entries that violate the nameConstraints of the issuing CA, and wolfSSL would accept them as valid.

CVSS3: 6.5
nvd
4 месяца назад

URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c. A compromised or malicious sub-CA could issue leaf certificates with URI SAN entries that violate the nameConstraints of the issuing CA, and wolfSSL would accept them as valid.

msrc
4 месяца назад

URI nameConstraints not enforced in ConfirmNameConstraints()

CVSS3: 6.5
github
4 месяца назад

URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c. A compromised or malicious sub-CA could issue leaf certificates with URI SAN entries that violate the nameConstraints of the issuing CA, and wolfSSL would accept them as valid.